Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2019-25544 Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long userna… Pidgin No fix yet Fix from $1,6002026-03-21 MEDIUM 5.5 CVE-2012-1257 Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor. Pidgin Mitigation only Fix from $1,6002019-11-20 HIGH 8.8 CVE-2016-2379 The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging know… Mxit Mitigation only Fix from $1,9502017-03-29 MEDIUM 6.4 CVE-2014-3697 Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to wri… Pidgin after 2.10.9 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-3695 markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via… Pidgin after 2.10.9 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-3696 nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (applicati… Pidgin after 2.10.9 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-3698 The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sen… Pidgin after 2.10.9 Fix from $1,6002014-10-29 HIGH 10.0 CVE-2013-6490EPSS 15% The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header,… Pidgin after 2.10.7 Fix from $1,9502014-02-06 HIGH 7.5 CVE-2013-6487EPSS 8% Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspeci… Pidgin after 2.10.7 Fix from $1,9502014-02-06 MEDIUM 5.0 CVE-2013-6481 libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message wit… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-6482 Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2)… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-6489EPSS 6% Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) … Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2014-0020 The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of … Pidgin after 2.10.7 Fix from $1,6002014-02-06 HIGH 9.3 CVE-2013-6486 gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: UR… Pidgin after 2.10.7 Fix from $1,9502014-02-06 MEDIUM 6.4 CVE-2013-6483 The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with … Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2012-6152 The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denia… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-6477 Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-6479 util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-6484 The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write op… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-6485 Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibl… Pidgin after 2.10.7 Fix from $1,6002014-02-06 MEDIUM 6.8 CVE-2013-0272 Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long… Pidgin after 2.10.6 Fix from $1,6002013-02-16 MEDIUM 5.0 CVE-2013-0271 The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2)… Pidgin after 2.10.6 Fix from $1,6002013-02-16 MEDIUM 5.0 CVE-2013-0273 sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote server… Pidgin after 2.10.6 Fix from $1,6002013-02-16 HIGH 7.5 CVE-2012-3374EPSS 6% Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a … Pidgin after 2.10.4 Fix from $1,9502012-07-07 MEDIUM 5.0 CVE-2012-2318 msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cau… Pidgin after 2.10.3 Fix from $1,6002012-07-03 MEDIUM 6.4 CVE-2011-4939 The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer der… Pidgin after 2.10.1 Fix from $1,6002012-03-15 MEDIUM 5.0 CVE-2012-1178 The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial … Pidgin after 2.10.1 Fix from $1,6002012-03-15 MEDIUM 5.0 CVE-2011-4601 family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, wh… Pidgin after 2.10.0 Fix from $1,6002011-12-25 MEDIUM 5.0 CVE-2011-4603 The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 valid… Pidgin after 2.10.0 Fix from $1,6002011-12-17 MEDIUM 5.0 CVE-2011-4602 The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, w… Pidgin after 2.10.0 Fix from $1,6002011-12-17